End-to-end information flow security model for~software-defined networks
Modelirovanie i analiz informacionnyh sistem, Tome 22 (2015) no. 6, pp. 735-749

Voir la notice de l'article provenant de la source Math-Net.Ru

Software-defined networks (SDN) are a novel paradigm of networking which became an enabler technology for many modern applications such as network virtualization, policy-based access control and many others. Software can provide flexibility and fast-paced innovations in the networking; however, it has a complex nature. In this connection there is an increasing necessity of means for assuring its correctness and security. Abstract models for SDN can tackle these challenges. This paper addresses to confidentiality and some integrity properties of SDNs. These are critical properties for multi-tenant SDN environments, since the network management software must ensure that no confidential data of one tenant are leaked to other tenants in spite of using the same physical infrastructure. We define a notion of end-to-end security in context of software-defined networks and propose a semantic model where the reasoning is possible about confidentiality, and we can check that confidential information flows do not interfere with non-confidential ones. We show that the model can be extended in order to reason about networks with secure and insecure links which can arise, for example, in wireless environments. The article is published in the authors' wording.
Keywords: SDN, security, formal models.
@article{MAIS_2015_22_6_a0,
     author = {D. Ju. Chaly and E. S. Nikitin and E. Ju. Antoshina and V. A. Sokolov},
     title = {End-to-end information flow security model for~software-defined networks},
     journal = {Modelirovanie i analiz informacionnyh sistem},
     pages = {735--749},
     publisher = {mathdoc},
     volume = {22},
     number = {6},
     year = {2015},
     language = {en},
     url = {http://geodesic.mathdoc.fr/item/MAIS_2015_22_6_a0/}
}
TY  - JOUR
AU  - D. Ju. Chaly
AU  - E. S. Nikitin
AU  - E. Ju. Antoshina
AU  - V. A. Sokolov
TI  - End-to-end information flow security model for~software-defined networks
JO  - Modelirovanie i analiz informacionnyh sistem
PY  - 2015
SP  - 735
EP  - 749
VL  - 22
IS  - 6
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/MAIS_2015_22_6_a0/
LA  - en
ID  - MAIS_2015_22_6_a0
ER  - 
%0 Journal Article
%A D. Ju. Chaly
%A E. S. Nikitin
%A E. Ju. Antoshina
%A V. A. Sokolov
%T End-to-end information flow security model for~software-defined networks
%J Modelirovanie i analiz informacionnyh sistem
%D 2015
%P 735-749
%V 22
%N 6
%I mathdoc
%U http://geodesic.mathdoc.fr/item/MAIS_2015_22_6_a0/
%G en
%F MAIS_2015_22_6_a0
D. Ju. Chaly; E. S. Nikitin; E. Ju. Antoshina; V. A. Sokolov. End-to-end information flow security model for~software-defined networks. Modelirovanie i analiz informacionnyh sistem, Tome 22 (2015) no. 6, pp. 735-749. http://geodesic.mathdoc.fr/item/MAIS_2015_22_6_a0/